Skip to content
Open access

METHODS FOR COUNTERING DATA POISONING DURING THE FINE-TUNING PHASE OF NEURAL NETWORKS

Jul 2026 · Advanced Information Systems · Vol 10, pp. 69-79 · 0 citations

TL;DR

A multi-loop protection system which protects the latent feature space through mathematical validation and guarantees the structural integrity of neural network models when transfer learning is applied in high-risk domains.

Abstract

Background. The research investigates how data poisoning attacks during fine-tuning stages make modern neural networks extremely vulnerable to attacks. The industry now focuses on domain-specific datasets, which attackers use to create unequal market advantages through their ability to hide backdoors with minimal changes to data. The current protection methods fail to provide proper security because they cause major memory loss of essential information, while attackers can bypass their protection mechanisms by using complex semantic attacks against systems which operate in decentralized federated learning environments. The research develops a multi-loop protection system which protects the latent feature space through mathematical validation. The proposed method combines neural network retraining with reverse analysis of synaptic weight changes to detect compromised neurons at a high level of precision, which does not affect the model's performance when working with unaltered data. The research bases its theoretical structure on the concept which protects distributed infrastructures through multiple layers of defense. The system uses local stochastic filtering operations which run on client devices through DP-SGD differential privacy mechanisms before servers perform semantic auditing with explainable artificial intelligence (XAI) for protection. This is then followed by smart contract-based cryptographic verification of update processes. The experimental data shows the results of the study. The developed architecture shows strong performance through empirical testing, which used benchmark architectures that included convolutional neural networks (CNNs) and large language models (LLMs) for critical application systems. The proposed multi-loop filter implementation enables the Attack Success Rate to achieve a zero limit, while it maintains the model's ability to predict correctly for legitimate data. Research conclusions. The results obtained from a robust theoretical and algorithmic foundation for the transition from reactive anomaly detection methods to proactive topological protection of intelligent systems. The developed methodology guarantees the structural integrity of neural network models when transfer learning is applied in high-risk domains.

Read PDF

Similar papers

Conference Aug 2026

Deep learning is applied in abnormal behavior recognition for data security protection

In the context of the widespread deployment of cloud computing and the Internet of Things, enterprise business systems are constantly exposed to the open network environment. Abnormal behavior identification has become a crucial link in the data security protection chain. Based on multi-source security logs and behavior sequence data, a deep learning anomaly identification model integrating embedded representation, bidirectional recurrent networks/Transformer encoding, attention weighting, and adaptive threshold control was constructed. An adversarial perturbation constraint and security interval loss were introduced to form a robust training framework. At the same time, an anomaly behavior interpretation and rule extraction mechanism based on attention weights and gradient contributions was designed to achieve a closed loop from model output to security policy generation. Experiments were conducted using approximately 3.2 million real business log data covering over 8,000 accounts and 1,200 hosts. Compared with rule detection, Isolation Forest, and ordinary sequence models, the proposed method achieved better performance in terms of F1 value (0.90) and AUC (0.94), with a false alarm rate reduced to 0.05. This validates the effectiveness of deep learning technology in improving the accuracy and stability of abnormal behavior identification in data security protection scenarios, providing a method reference for building interpretable and scalable intelligent security protection systems in complex business environments.

Shuai Long, Zeliang Xiao · 0 citations
Open access Aug 2026

Detection of DDoS Attacks in Networks Using Deep Learning Based on Long Short-Term Memory (LSTM)

HTTP Flood attacks remain difficult to detect because they operate at the application layer, resemble legitimate user requests, and generate burst-based temporal traffic patterns. Previous DDoS detection studies often rely on outdated datasets, process network flows as independent records, insufficiently address class imbalance, and provide limited interpretability for security analysts. This study proposes a sequence-aware and explainable deep learning framework for HTTP Flood detection using Long Short-Term Memory (LSTM). Reconstructed HTTP traffic from the UNSW-NB15 dataset was processed through proxy labeling, data cleaning, feature normalization, and sliding-window transformation to convert flow-level records into temporal sequences. Class weighting and SMOTE oversampling were evaluated to mitigate imbalance, while SHAP and LIME were used to explain model decisions. The proposed LSTM model achieved an attack recall of 94.8%, a false negative rate of 5.2%, balanced accuracy of 94.3%, MCC of 0.824, and ROC-AUC of 0.975. The results show that temporal representation improves detection of bursty HTTP Flood behavior, whereas class weighting provides a better balance between attack sensitivity and false-alarm control. Explainability analysis further confirms that the model relies on technically meaningful indicators, including packet rate, flow duration, traffic asymmetry, and service concentration. This framework supports interpretable early-warning detection for application-layer DDoS attacks.

Dicky Surya Dwi Putra, Nomsa Ramaphosa · 0 citations
Book Open access Aug 2026

Defending against Model Extraction for GNNs with Model Reprogramming

Graph Neural Networks (GNNs) serve as the backbone for high-stakes applications in Machine-Learning-as-a-Service (MLaaS). Still, their black-box deployment exposes them to Model Extraction (ME) attacks, in which adversaries steal intellectual property by querying APIs. Existing defenses suffer from a critical ''Euclidean bias'': they transfer image-based strategies (e.g., random noise) to graphs, ignoring the complex topological dependencies between nodes, which often results in severe utility degradation. Passive methods like watermarking also fail to prevent theft in real time. To bridge this gap, we propose GraphRP (Graph Reprogramming Protection), a proactive defense framework that repurposes Model Reprogramming for security. Unlike static perturbations, GraphRP introduces a Structure-Aware Gating Mechanism driven by learnable topological prototypes. This creates a dynamic ''structural firewall'' that selectively modulates the model's decision boundary: it preserves fidelity for benign queries residing on the training manifold, while maximizing the Fisher Information along the perturbation direction for adversarial queries. Under standard assumptions (bounded loss, optimal attacker, and local second-order approximation), we prove a lower bound on the attacker's estimation error that increases with the structural sensitivity of the reprogramming noise. Extensive experiments on both hard-label and soft-label ME attacks demonstrate that GraphRP significantly degrades attack effectiveness while preserving benign utility.

Yan Wen, Zhenyi Wang, Heng Huang · 0 citations
Open access Jul 2026

A Comprehensive Defense Framework Against Poisoning Backdoor Attacks in Federated Learning

This work employs the novel dimensionality reduction technique UMAP and a stringent filtering mechanism to effectively identify and exclude potential malicious participants without relying on traditional noise addition methods and demonstrates that the proposed method maintains high main task accuracy while effectively mitigating backdoor attacks across various attack scenarios.

Chun-I Fan, Hsin-Yen Wang, Tomohiro Morikawa · 0 citations
Conference Open access 2026

Generalizing across Networks: Evaluating Model Transferability for Intrusion Detection

This study evaluates the generalization capability of models such as LGBM, RF, XGB, and LSTM, particularly in identifying previously unseen attacks, and investigated the impact of feature selection on generalization and examined how performance changes when combining different datasets.

Miguel Silva, J. Vitorino, Daniela Pinto et al. · 0 citations
Open access Aug 2026

A hybrid machine and deep learning model for detecting DDoS attacks

A hybrid model combining Machine Learning and Deep Learning algorithms is introduced to enhance the detection of DDoS attacks, showing promising results in DDoS attack detection scenarios.

E. Hossny, Amal M. Al-Eryani, F. Omara · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.